CVE-2026-31027
CRITICALTOTOlink A3600R v5.9c.4959 - Buffer Overflow
Title source: llmDescription
TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste_modules/app.so. The vulnerability occurs because the rootSsid parameter is not properly validated for length, allowing remote attackers to trigger a buffer overflow, potentially leading to arbitrary code execution or denial of service.
Scores
CVSS v3
9.8
EPSS
0.0078
EPSS Percentile
73.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-120
Status
published
Products (1)
totolink/a3600r_firmware
5.9c.4959
Published
Apr 01, 2026
Tracked Since
Apr 01, 2026